FINTRAC's enforcement surge: what two years of penalties tell us
Administrative monetary penalties have accelerated sharply since 2024. Here's what the pattern reveals about regulator priorities, and where lean compliance teams are most exposed.
Over the last 24 months, FINTRAC has moved from a posture of guidance and remediation to one of visible, public enforcement. The number of administrative monetary penalties (AMPs) issued, and the average dollar value attached to each, has climbed in a way that cannot be dismissed as an isolated cycle. For Canadian non-bank reporting entities, this is the single most important compliance trend to absorb.
What changed in FINTRAC's enforcement approach?
Three things shifted in parallel. First, FINTRAC's examination capacity expanded, which means more entities are seeing on-site or virtual examinations on shorter cycles. Second, the regulator narrowed its tolerance for the same recurring deficiencies, incomplete risk assessments, late or missing reports, weak ongoing monitoring, and training gaps. Third, the public naming convention has been used more aggressively, turning what used to be a private compliance matter into a reputational event.
Where are the penalties landing?
Looking across published notices, four categories of violation drive the majority of recent AMPs:
- Failure to submit suspicious transaction reports (STRs), or submitting them late, without sufficient narrative, or without supporting evidence.
- Deficient compliance program documentation, risk assessments that are generic, policies that don't match actual operations, or training records that can't be produced.
- Inadequate ongoing monitoring, relationships rated low risk that should have been escalated, or risk ratings that were never refreshed after material changes.
- Recordkeeping failures, missing beneficial ownership information, incomplete know-your-client (KYC) records, or transaction records that can't be reconstructed for an examiner.
Why are lean compliance teams most exposed?
Larger banks absorb examination findings inside dedicated remediation programs. Money services businesses, payment service providers, crypto firms, and credit unions typically don't have that buffer. A single examination cycle can surface dozens of findings, and the cost of remediation, consultants, software, hiring, frequently exceeds the AMP itself. The compounding effect is what makes this trend particularly painful for sub-100-person firms.
What does a strong compliance program look like in 2026?
Firms that come through examinations cleanly tend to share a few traits. Their risk assessment is a living document tied to actual customer and transaction data, not a PDF refreshed annually. Their alerts and cases produce a defensible audit trail by default, with timestamps, decisions, and evidence attached. Their training is role-specific and tracked. And they can produce any record an examiner asks for in minutes, not days.
The takeaway
The enforcement curve is unlikely to flatten. The firms that treat compliance as an operating system, not a binder, are the ones avoiding the headlines. Every other firm is one examination away from finding out where their gaps are.
FAQ
How big has FINTRAC's enforcement surge been since 2024?
Since 2024, FINTRAC's enforcement surge has been substantial in both the number of administrative monetary penalties issued and the average dollar value attached to each. The regulator moved from a posture of guidance and remediation to visible, public enforcement, and the climb cannot be dismissed as an isolated cycle. Three shifts drove it in parallel: examination capacity expanded, so more entities face on-site or virtual examinations on shorter cycles; tolerance for recurring deficiencies narrowed; and the public naming convention was used more aggressively, turning a private compliance matter into a reputational event. The pattern reflects an explicit priority to move the regime toward outcomes-based, dissuasive enforcement. For Canadian non-bank reporting entities, this is the single most important compliance trend to absorb, because the curve is unlikely to flatten and every unaddressed gap now carries a larger and more public downside.
Which sectors are driving the AMP increases?
Money services businesses, including foreign MSBs operating into Canada, payment service providers entering the formal regulatory perimeter, and crypto-asset service providers with high transaction velocity have driven the bulk of the AMP increase. The common thread is exposure without a buffer. Larger banks absorb examination findings inside dedicated remediation programs, but these leaner sectors typically do not have that cushion. A single examination cycle can surface dozens of findings, and the cost of remediation, consultants, software, and hiring, frequently exceeds the penalty itself. That compounding effect is what makes the trend particularly painful for sub-100-person firms. The four violation categories behind most recent penalties are foundational rather than exotic: missing or late suspicious transaction reports, deficient compliance program documentation, inadequate ongoing monitoring, and recordkeeping failures. Any firm concentrated in these sectors should assume it is on a shorter examination cycle and price the downside accordingly.
What deficiencies are FINTRAC examiners finding most often?
Examiners keep finding the same foundational deficiencies, and four categories drive the majority of recent penalties. First, suspicious transaction reports that are missing, late, or filed without sufficient narrative or supporting evidence. Second, deficient compliance program documentation: risk assessments that are generic, policies that do not match actual operations, and training records that cannot be produced. Third, inadequate ongoing monitoring, where relationships rated low risk should have been escalated, or risk ratings were never refreshed after material changes. Fourth, recordkeeping failures such as missing beneficial ownership information, incomplete know-your-client records, or transaction records that cannot be reconstructed for an examiner. None of these are exotic; they are the basic pillars every program is supposed to cover. That is why they recur, and why an audit trail that reconstructs decisions by default, with timestamps and evidence attached, is the trait firms that pass examinations tend to share.
Does the enforcement surge change anything for small firms?
Yes, and small firms are the least protected from the trend, not the most. The per-occurrence model means a single foundational deficiency aggregates fast across a customer book or a reporting period, so a lean firm can face a total that looks nothing like a single fine. Larger banks absorb examination findings inside dedicated remediation programs; money services businesses, payment service providers, crypto firms, and credit unions typically have no such buffer. A single examination cycle can surface dozens of findings, and the cost of remediation, consultants, software, and hiring, frequently exceeds the penalty itself. The surge is calibrated to make the cost of non-compliance exceed the cost of fixing the program, which is the behavioural change it is designed to drive. The firms that treat compliance as an operating system rather than a binder are the ones avoiding the headlines; every other firm is one examination away from finding its gaps.
Sources
Reading is useful. A conversation is faster.
Book a platform demo and we will walk you through real-time sanctions, PEP, and adverse-media screening and the data coverage that fits your firm.
Book a call
